< Back to all clusters
[BUSINESS] · Austria · 2 sources

started · updated

Austrian Supreme Court rules credit agencies violated GDPR

The Supreme Court of Austria has ruled that credit reporting agencies, specifically CRIF, violated the GDPR principle of purpose limitation. The court determined that using data purchased from address publishers for credit scoring is unlawful, as those publishers are only permitted to collect and process data for marketing purposes under trade regulations.

Because the use of such data for identity and credit checks constitutes a change in purpose that was not covered by the original collection intent, the court ruled that explicit consent from the affected individuals would have been required.

The decision follows years of litigation. In response to the ruling, the privacy organization noyb, founded by Max Schrems, is preparing a class-action lawsuit. The organization aims to seek potential damages of approximately 500 euros for each affected individual.

Entities

AZ Direct · CRIF · Max Schrems · Supreme Court of Austria · noyb